-
- Downloads
Change single Vault pki mount to multi pki mounts paths for etcd and kube CA`s (#1552)
* Added update CA trust step for etcd and kube/secrets roles * Added load_balancer_domain_name to certificate alt names if defined. Reset CA's in RedHat os. * Rename kube-cluster-ca.crt to vault-ca.crt, we need separated CA`s for vault, etcd and kube. * Vault role refactoring, remove optional cert vault auth because not not used and worked. Create separate CA`s fro vault and etcd. * Fixed different certificates set for vault cert_managment * Update doc/vault.md * Fixed condition create vault CA, wrong group * Fixed missing etcd_cert_path mount for rkt deployment type. Distribute vault roles for all vault hosts * Removed wrong when condition in create etcd role vault tasks.
Showing
- docs/vault.md 15 additions, 12 deletionsdocs/vault.md
- roles/etcd/defaults/main.yml 2 additions, 0 deletionsroles/etcd/defaults/main.yml
- roles/etcd/tasks/gen_certs_script.yml 0 additions, 27 deletionsroles/etcd/tasks/gen_certs_script.yml
- roles/etcd/tasks/gen_certs_vault.yml 2 additions, 0 deletionsroles/etcd/tasks/gen_certs_vault.yml
- roles/etcd/tasks/main.yml 3 additions, 0 deletionsroles/etcd/tasks/main.yml
- roles/etcd/tasks/upd_ca_trust.yml 27 additions, 0 deletionsroles/etcd/tasks/upd_ca_trust.yml
- roles/kubernetes/secrets/defaults/main.yml 1 addition, 0 deletionsroles/kubernetes/secrets/defaults/main.yml
- roles/kubernetes/secrets/tasks/gen_certs_script.yml 0 additions, 27 deletionsroles/kubernetes/secrets/tasks/gen_certs_script.yml
- roles/kubernetes/secrets/tasks/gen_certs_vault.yml 22 additions, 6 deletionsroles/kubernetes/secrets/tasks/gen_certs_vault.yml
- roles/kubernetes/secrets/tasks/main.yml 3 additions, 0 deletionsroles/kubernetes/secrets/tasks/main.yml
- roles/kubernetes/secrets/tasks/upd_ca_trust.yml 27 additions, 0 deletionsroles/kubernetes/secrets/tasks/upd_ca_trust.yml
- roles/reset/tasks/main.yml 8 additions, 2 deletionsroles/reset/tasks/main.yml
- roles/vault/defaults/main.yml 25 additions, 15 deletionsroles/vault/defaults/main.yml
- roles/vault/tasks/bootstrap/ca_trust.yml 3 additions, 3 deletionsroles/vault/tasks/bootstrap/ca_trust.yml
- roles/vault/tasks/bootstrap/create_etcd_role.yml 14 additions, 6 deletionsroles/vault/tasks/bootstrap/create_etcd_role.yml
- roles/vault/tasks/bootstrap/gen_auth_ca.yml 0 additions, 21 deletionsroles/vault/tasks/bootstrap/gen_auth_ca.yml
- roles/vault/tasks/bootstrap/gen_vault_certs.yml 2 additions, 1 deletionroles/vault/tasks/bootstrap/gen_vault_certs.yml
- roles/vault/tasks/bootstrap/main.yml 36 additions, 23 deletionsroles/vault/tasks/bootstrap/main.yml
- roles/vault/tasks/bootstrap/role_auth_cert.yml 0 additions, 26 deletionsroles/vault/tasks/bootstrap/role_auth_cert.yml
- roles/vault/tasks/bootstrap/role_auth_userpass.yml 0 additions, 11 deletionsroles/vault/tasks/bootstrap/role_auth_userpass.yml
roles/etcd/tasks/upd_ca_trust.yml
0 → 100644
Please register or sign in to comment